Article about new "Reaper" or "loTroop" Botnet

According to https://research.checkpoint.com/new-iot-botnet-storm-coming/
There is a new botnet more powerful than Murai, and it does state it can grab Tik devices, It lists possible vulerabilities as:
MikroTik RouterOS SNMP Security Bypass –
MikroTik RouterOS Admin Password Change –
Mikrotik Router Remote Denial Of Service -
I’m assuming with atleast the default firewall, and a good user/pass, you should be okay. Not trying to startle up the tin-foil-wearing-folk, just wanted to bring this to attention as they do list Mikrotik in their article.

If You read carefully, these are issues not related to this attack, only can be potentially exploited (at least, Checkpoint thinks so). As said before in one of posts in this forum, if You are on latest versions of ROS, You are OK.

i think the main reason of mikrotik mention in that topic its about bad configured devices, simple passwords or any password at all, dns and ntp servers open to internet etc etc

i think is a good think mikrotik now is brand big enough to be taken into account, that speaks loud about the number of mikrotik devices deployed in internet

The only conclusion I draw from that table is that MT equipment his NOT involved. At least this is what those “-” signs suggest. The mere fact that it appears in that table just shows that MT is important enough to be mentioned, not that it is vulnerable.

I just found it interesting and worth sharing. :slight_smile: I use a robust firewall, only limit certain IP Services to certain IP’s, and all my passwords are complex.
But anything mentioning MikroTik is worth mentioning here.

Your post title and post itself is very wrong. Did you read the article?
It clearly says: “Seen in the Context of the current Attack?” MikroTik = NO

Exactly the opposite of what you said.
MikroTik is NOT vulnerable.